Group Purchasing
Group Purchasing

macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses

macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses (PDF, 1.68MB)Published: 22 Jun, 2026
Created by:
Cory Findley

Focusing on the behaviors macOS infostealers use to exfiltrate data is important for implementing effective defenses.

This paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis. Infostealer samples were run in a macOS sandbox environment to analyze how specific malware families exfiltrate data. Analysis shows that multiple malware families use the native utility, curl, commonly for exfiltration. Command-line options and arguments vary across malware families, indicating that infostealer exfiltration can be detected and triaged when detections are tailored to find exfiltration activity. This can lead to multiple approaches for security teams when developing detection rules and modeling cyber threats.